plugin

Hydra Booking Vulnerabilities

22 known security issues reported for the Hydra Booking WordPress plugin. Most recent disclosed Aug 14, 2026.

1 critical 2 high 11 medium

Running Hydra Booking on your site? Check whether your installed version is affected.

Scan your site free

Hydra Booking <= 1.2.2 - Authenticated (Host+) Stored Cross-Site Scripting via 'first_name' Parameter

medium

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 1.2.2
Fixed in:
1.2.3
Disclosed:
Aug 14, 2026

CVE-2026-15948 on NVD →

Hydra Booking <= 1.2.2 - Missing Authorization

medium

The Hydra Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.2.2
Fixed in:
1.2.3
Disclosed:
Aug 13, 2026

CVE-2026-28188 on NVD →

Hydra Booking <= 1.2.1 - Authenticated (Custom+) Insecure Direct Object Reference to Sensitive Information Exposure via 'booking_id' Parameter

medium

The Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.2.1 via the /wp-json/hydra-booking/v1/booking/details/{id} REST endpoint. This is due to the getBookingDetails() callback only enforcing the tfhb_manag...

CVSS:
4.3
Affected:
up to 1.2.1
Fixed in:
1.2.2
Disclosed:
Jul 8, 2026

CVE-2026-12433 on NVD →

Hydra Booking — Appointment Scheduling & Booking Calendar <= 1.1.44 - Unauthenticated Stored Cross-Site Scripting

high

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.44 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

CVSS:
7.2
Affected:
up to 1.1.44
Fixed in:
1.1.45
Disclosed:
Jul 8, 2026

CVE-2026-57388 on NVD →

Hydra Booking — Appointment Scheduling & Booking Calendar <= 1.1.41 - Missing Authorization

medium

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.1.41. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.1.41
Fixed in:
1.1.42
Disclosed:
May 15, 2026

CVE-2026-42675 on NVD →

Hydra Booking <= 1.1.38 - Authenticated (Hydra host+) Stored Cross-Site Scripting

medium

The Hydra Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with hydra host-level access and above, to inject arbitrary web scripts in pages th...

CVSS:
6.4
Affected:
up to 1.1.38
Fixed in:
1.1.39
Disclosed:
Feb 15, 2026

CVE-2026-39541 on NVD →

Hydra Booking — Appointment Scheduling &amp; Booking Calendar [hydra-booking] <= 1.1.32 (unfixed)

unknown

[en] Incorrect Privilege Assignment vulnerability in Themefic Hydra Booking hydra-booking allows Privilege Escalation.This issue affects Hydra Booking: from n/a through <= 1.1.32.

Affected:
up to 1.1.32
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-68027 on NVD →

Hydra Booking <= 1.1.32 - Unauthenticated Privilege Escalation

critical

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.32. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.

CVSS:
9.8
Affected:
up to 1.1.32
Fixed in:
1.1.33
Disclosed:
Jan 21, 2026

CVE-2025-68027 on NVD →

Hydra Booking — Appointment Scheduling &amp; Booking Calendar [hydra-booking] <= 1.1.32 (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL Injection.This issue affects Hydra Booking: from n/a through <= 1.1.32.

Affected:
up to 1.1.32
Fix:
No patched version reported
Disclosed:
Dec 16, 2025

CVE-2025-68055 on NVD →

Hydra Booking <= 1.1.32 - Authenticated (Custom role+) SQL Injection

medium

The Hydra Booking plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom role-level access and a...

CVSS:
6.5
Affected:
up to 1.1.32
Fixed in:
1.1.33
Disclosed:
Nov 27, 2025

CVE-2025-68055 on NVD →

Hydra Booking — Appointment Scheduling &amp; Booking Calendar [hydra-booking] < 1.1.28

unknown

[en] The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to missing payment verification to unauthenticated payment bypass in all versions up to, and including, 1.1.27. This is due to the plugin accepting client-controlled payment confirmation data in the tfhb_meeting_paypal...

Affected:
up to 1.1.28
Fixed in:
1.1.28
Disclosed:
Nov 11, 2025

CVE-2025-12788 on NVD →

Hydra Booking — Appointment Scheduling &amp; Booking Calendar [hydra-booking] < 1.1.28

unknown

[en] The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booking cancellation in all versions up to, and including, 1.1.27. This is due to the plugin's "tfhb_meeting_form_submit_callback" function using insufficiently random values to generate booking cancell...

Affected:
up to 1.1.28
Fixed in:
1.1.28
Disclosed:
Nov 11, 2025

CVE-2025-12787 on NVD →

Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Missing Payment Verification to Unauthenticated Payment Bypass

medium

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to missing payment verification to unauthenticated payment bypass in all versions up to, and including, 1.1.27. This is due to the plugin accepting client-controlled payment confirmation data in the tfhb_meeting_paypal_paym...

CVSS:
5.3
Affected:
up to 1.1.27
Fixed in:
1.1.28
Disclosed:
Nov 10, 2025

CVE-2025-12788 on NVD →

Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Unauthenticated Arbitrary Booking Cancellation via Weak Hash Generation

medium

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booking cancellation in all versions up to, and including, 1.1.27. This is due to the plugin's "tfhb_meeting_form_submit_callback" function using insufficiently random values to generate booking cancellation...

CVSS:
5.3
Affected:
up to 1.1.27
Fixed in:
1.1.28
Disclosed:
Nov 10, 2025

CVE-2025-12787 on NVD →

Hydra Booking — Appointment Scheduling &amp; Booking Calendar [hydra-booking] <= 1.1.9 (unfixed)

unknown

[en] Missing Authorization vulnerability in Themefic Hydra Booking hydra-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hydra Booking: from n/a through <= 1.1.9.

Affected:
up to 1.1.9
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-49377 on NVD →

Hydra Booking — Appointment Scheduling &amp; Booking Calendar [hydra-booking] <= 1.1.10 (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL Injection.This issue affects Hydra Booking: from n/a through <= 1.1.10.

Affected:
up to 1.1.10
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-49378 on NVD →

Hydra Booking 1.1.0 - 1.1.18 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via tfhb_reset_password_callback Function

high

The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tfhb_reset_password_callback() function in versions 1.1.0 to 1.1.18. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the password of an Administrator...

CVSS:
8.8
Affected:
1.1.0 – 1.1.18
Fixed in:
1.1.19
Disclosed:
Jul 28, 2025

CVE-2025-7689 on NVD →

Hydra Booking <= 1.1.10 - Authenticated (Subscriber+) SQL Injection

medium

The Hydra Booking plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and ab...

CVSS:
6.5
Affected:
up to 1.1.10
Fixed in:
1.1.11
Disclosed:
Jun 12, 2025

CVE-2025-49378 on NVD →

Hydra Booking <= 1.1.9 - Missing Authorization

medium

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an u...

CVSS:
4.3
Affected:
up to 1.1.9
Fixed in:
1.1.10
Disclosed:
Jun 12, 2025

CVE-2025-49377 on NVD →

Hydra Booking — Appointment Scheduling &amp; Booking Calendar [hydra-booking] < 1.1.11

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking allows SQL Injection. This issue affects Hydra Booking: from n/a through 1.1.10.

Affected:
up to 1.1.11
Fixed in:
1.1.11
Disclosed:
Jun 6, 2025

CVE-2025-49323 on NVD →

Hydra Booking <= 1.1.10 - Authenticated (Contributor+) SQL Injection

medium

The Hydra Booking plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and...

CVSS:
6.5
Affected:
up to 1.1.10
Fixed in:
1.1.11
Disclosed:
Jun 5, 2025

CVE-2025-49323 on NVD →

Hydra Booking — Appointment Scheduling &amp; Booking Calendar [hydra-booking] >= 1.1.0 - < 1.1.19

unknown
Affected:
1.1.0 – 1.1.19
Fixed in:
1.1.19

CVE-2025-7689 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database